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REMARKS/ARGUMENTS 
Applicants canceled the non-elected claims 

Applicants amended claims 6 and 3 1 to correct a punctuation error by adding a period at 
the end of the sentences. 

The Examiner rejected claims 1-10, 17-22, and 26-35 as anticipated (35 U.S.C. §102(e)) 
by Mayer (U.S. Patent Pub. No. 2004/0034794). Applicants traverse. 

Claims 1,17, and 26 require processing a file request to operate on a target file that is 
directed to a file system; determining whether a rule specifies a file attribute satisfied by the 
target file; in response to determining that the target file satisfies the file attribute of the 
determined rule, determining whether a condition specified by the determined rule is satisfied; in 
response to determining that the condition is satisfied, performing an action specified by the 
determined rule; and forwarding the file request to the file system to execute if the rule does not 
inhibit the file request. 

The Examiner cited FIG. 2 and para. [0035] of Mayer as disclosing the claim requirement 
of determining whether a rule specifies a file attribute satisfied by the target file. The cited FIG. 
2 shows a hooked file system fiinction 200. A hooked fiinction refers to an executable filtering 
code placed between the calling code and called function and has the ability to monitor, intercept 
and redefine the fiinction that is being hooked. (Mayer, col. P. 5, para. [0079]). 

Nowhere does the cited FIG. 2 which shows a hooked fiinction disclose determining 
whether a rule specifies a file attribute satisfied by the target file. FIG. 2 does show tracking file 
parameters (211). Mayer mentions that the file parameters are tracked 211 and stored in the 
database for fiirther use, such as for statistics. (Mayer, para. [0129], pg. 17). Although the cited 
FIG. 2 mentions tracking file parameters, nowhere is there any disclosure of the claim 
requirement of determining whether a rule specifies a file attribute satisfied by the target file. 

The cited para. [0035] mentions a database for storing default rules, which contain a set 
of rules that are good for most users, user defined rules, and statistics of normal behavior of 
programs which is learned during the system operation. The database contains authorizations 
and a log of questions that the security system asked the user, and a log of suspicious activities , 
detected. 
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Although the cited para. [0035] discusses rules and authorizations, nowhere is there any 
disclosure or mention of the claim requirement of determining whether a rule specifies a file 
attribute satisfied by the target file subject to the file request. 

The Examiner cited the above discussed para, [0035] and FIG. 2 as disclosing the claim 
requirement of in response to determining that the target file satisfies the file attribute of the 
determined rule, determining whether a condition specified by the determined rule is satisfied. 
(Office Action, pg, 4) Applicants traverse. 

As discussed , the cited para. [0035] discusses a database of rules, authorizations, a log of 
questions asked the user and replies, and a log of suspicious activities. Nowhere is there any 
disclosure in the cited para. [0035] of determining whether a conditions specified by the 
determined rule is satisfied in response to determining that the target file satisfies the file 
attribute of the determined rule. Instead, the cited para. [0035] discusses rules in general and 
logging suspicious activities. There is no disclosure of the specific claim requirements of 
determining whether a rule condition is satisfied in response to determining that the target file 
satisfies the file attribute of the determined rule. 

Further, as discussed, the cited FIG. 2 discusses tracking file parameters for uses, such as 
statistics, as mentioned in para. [0129]. However, there is no disclosure of the claim requirement 
of determining whether a rule condition is satisfied in response to determining that the target file 
satisfies the file attribute of the determined rule. 

Yet further, the cited para. [0129] discusses monitoring and authorizing access to hooked 
fimctions that are called due to a disk related action, where hooked a fiinction refers to an 
executable filtering code placed between the calling code and called function and has the ability 
to monitor, intercept and redefine the function that is being hooked. Parameters, such as file 
action parameters are tracked and if needed stored in the database for further use such as 
statistics. If hacking is spotted, the security system proceeds to a special termination process, or 
ask for permission fi-om the user to terminate the process. 

The cited para. [0129] concerns monitoring and checking hooked functions making calls. 
There is no disclosure of the specific claim requirement of determining whether a rule condition 
is satisfied in response to determining that the target file satisfies the file attribute of the 
determined rule. 
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Moreover, the cited Mayer teaches away from the claim requirement of determining file 
attributes of the target file to determine whether a condition of a rule is satisfied. In the cited 
Mayer there is no need to examine a file attribute in a rule to determine whether the rule and 
action applies because in Mayer the rules are applied to hooked functions, such that filtering 
code between the calling code and calling function is used to intercept and monitor the hooked 
function. Thus, in the cited Mayer there is no checking of the file attribute of the target file to 
determine if a rule applies because filtering code is used to monitor calls and apply rules when a 
call is made to the fimction that is being hooked. Thus, in the cited Mayer filtering code is used 
to trigger the applying of rules and condition testing, not the file attributes of the target file as 
claimed. 

Accordingly, claims 1,17, and 26 are patentable over the cited art because the cited 
Mayer does not disclose all the claim requirements. 

Claims 2-10, 18-22, and 27-35 are patentable over the cited art because they depend from 
claims 1,17, and 26, which are patentable over the cited art for the reasons discussed above. 
Moreover, the following discussed claims provide additional grounds of patentability over the 
cited art. 

Claims 2 and 27 depend from claims 1 and 26 and further require determining whether 
one rule specifies the file attribute comprises processing file attributes associated with the target 
file to determine whether the file attributes include the rule. 

The Examiner cited para. [0130], lines 10-18 of Mayer as disclosing the additional 
requirements of these claims. (Office Action, pg. 4) Applicants traverse. 

The cited para. [0130] mentions that file parameters are tracked and if needed, relevant 
parts are stored in database for further use, such as statistics. An access to rules settings in the 
database is made to check whether the current action is permitted. 

Although the cited para. [0130] discusses tracking file parameters to store for later use, 
such as for statistics, nowhere is there any disclosure of processing file attributes to determine 
whether the file attributes are included in a rule. There is no disclosure in the cited para. [0130] 
of checking whether file attributes for a target file are included in a rule. Instead, the cited para. 
[0130] discusses tracking file parameters. 

Accordingly, claims 2 and 27 provide additional grounds of patentability over the cited 
art because the additional requirements of these claims are not disclosed in the cited art. 



Page 10 of 15 



Amdt. dated August 2, 2006 Serial No. 10/681 ,557 

Reply to Office Action of May 2, 2006 Docket No. SJO920030050US1 

Firm No. 0037.0053 

Claims 3, 18, and 28 depend from claims 1, 17, and 26 and further require that 
determining whether the rule specifies the file attribute comprises: processing s rules database 
including a plurality of rules, where each rule indicates a file attribute, a condition, and an action 
performed if the condition and file attribute are satisfied. 

The Examiner cited para. [0132] of Mayer as disclosing the additional requirements of 
these claims. (Office Action, pgs. 4-5). Applicants traverse. 

The cited para. [0132] mentions that when executable files are being loaded for 
execution, the security system is notified and checks it before it starts running. The file is being 
accessed in an earlier phase when the security system permits the access to the file. The security 
system tracks file parameters and relevant data for further use, stores that in the database and if 
needed passes the parameters. 

Although the cited para. [0132] discusses checking an executable file before it starts 
running and tracking and storing file parameters, nowhere is there any disclosure that each rule 
in the rules database indicates a file attribute, a condition and an action performed if the 
condition and file attribute are satisfied. Instead, the cited para. [0132] discusses checking 
performed before executing a file. Further, although the cited para. [0132] discusses tracking 
and storing file parameters, there is no disclosure that each rule in the rules database indicates a 
file attribute and condition such that the action is performed if the file attribute of the target file 
and condition is satisfied. 

Further, although the cited para. [0132] discusses monitoring for a specific type of files, 
i.e., executable files, this does not disclose that the rules including the action and condition also 
include a file attribute. Instead, in the cited para. [0132] the security system is notified when a 
file is executed so it may check whether execution can proceed. The Examiner has not cited any 
part of Mayer that discloses that the rule indicates a file attribute and that the condition and 
action are processed only after determining that the file attribute in the rule is satisfied by the 
target file. Instead, in Mayer, the checking is performed when the security system is notified that 
a hooked function has been called. The hooked function involves filtering code between the 
calling code and called function to monitor, intercept and redefine the fimction being hooked. 
Thus, the cited Mayer does not need to determine rules that apply to target files having certain 
file attributes indicated in the rule because the checking in Mayer is performed for called 
functions or when files are executed. 
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Accordingly, claims 3, 18, and 28 provide additional grounds of patentability over the 
cited art because the additional requirements of these claims are not disclosed in the cited art. 

Claims 4, 19, and 29 depend from claims 3, 18, and 28 and further require that rules in 
the rules database implement space management, security, and data protection policies. 

The Examiner cited lines 1-6 of para. [0129] of Mayer as disclosing the additional 
requirements of these claims. (Office Action, pg. 5) Applicants traverse. 

The cited para. [0129] mentions monitoring, checking and authorizing access to hooked 
functions that are called due to a disk related action. Other parts of Mayer discuss monitoring a 
call to a function for security reasons. However, the Examiner has not cited any part of Mayer 
that discloses that that the rules in the rules database implements space management and data 
protection policies. Instead, the cited Mayer discusses monitoring for security reasons. 

Accordingly, claims 4, 19, and 29 provide additional grounds of patentability over the 
cited art because the additional requirements of these claims are not disclosed in the cited art. 

Claims 5 and 30 depend from claims 3 and 28 and further require that a plurality of rules 
apply to the file request to determine whether to execute multiple actions in response to the file 
request. 

The Examiner cited para. [0133] of Mayer as disclosing the above claim requirements. 
(Office Action, pg. 5) Applicants traverse. 

The cited para. [0133] mentions monitoring, checking and authorizing access to hooked 
functions that are called due to a memory related action. The security system retrieves the 
caller's identify, relevant information from the database, the self-allocated memory, and checks 
if the process exceeds its memory borders. If the memory borders of the hooked function are 
exceeded, the security system can ask for permission from the user or terminate the process. 

Although the cited para. [0133] discusses how to check whether a function has exceeded 
its allocated memory borders for execution, there is no disclosure or mention in the cited para. 
[0133] that a plurality of rules apply to the file request and determining whether to execute 
multiple actions in response to the file request. In fact, the cited para. [0133] appears to only 
discuss one rule to apply to the request, a rule determining whether the memory borders are 
executed, not a plurality of rules to apply to the file request as claimed. 

Accordingly, claims 5 and 30 provide additional grounds of patentability over the cited 
art because the additional requirements of these claims are not disclosed in the cited art. 
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Claims 6 and 3 1 depend from claims 1 and 17 and further require that the file attribute of 
the rule is used to apply the action specified in the rule to files having at least one of the 
attributes comprising: a file name, a file directory, a file size, a file type, and an application 
originating the request. 

The Examiner cited para. [0129], lines 1-13 of Mayer as disclosing the additional 
requirements of these claims. (Office Action, pg. 5) Applicants traverse. 

The cited para. [0129] mentions a method for monitoring, checking and authorizing 
access to hooked functions that are called due to a disk related action. The function is tunneled 
to the proper method of access. The security system retrieves the caller's identity and required 
file action parameters. These file parameters are tracked and if needed stored in the database for 
further use, such as statistics. An access to rules settings is made to check whether the current 
action is permitted to prevent hacking. 

The cited para. [0129] discusses checking a function call, hooked function, to determine 
if the function call may proceed. Nowhere does the cited para. [0129] disclose that the file 
attribute is used to apply the action to files having at least one of the attributes comprising: a file 
name, a file directory, a file size, a file type, and an application originating the request. In the 
cited Mayer there is no need to examine a file attribute in a rule to determine whether the rule 
and action applies to files having a file attribute because in Mayer the rules are applied to hooked 
fiinctions, such that filtering code between the calling code and calling function is used to 
intercept and monitor the hooked function. Thus, in the cited Mayer there is no checking of the 
file attribute of the target file to determme if a rule applies because filtering code is used to 
monitor calls and apply rules, not file attributes as claimed. 

Accordingly, claims 6 and 31 provide additional grounds of patentability over the cited 
art because the additional requirements of these claims are not disclosed in the cited art. 

Claims 9 21, and 34 depend from claims 1,17, and 26 and further require that the file 
request is to add the target file to the file system, and wherein the attribute and condition 
specified in the rule check whether the target file is of a specified type and size threshold, 
wherein the action blocks the file request to add the target file if the specified type and size 
threshold is exceed or passes the file request to the file system to execute if the specified type is 
satisfied and the specified size threshold is not satisfied. 
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The Examiner cited para. [0130], lines 20-3 1 of Mayer as disclosing the requirements of 
these claims. (Office Action, pg. 6) Applicants traverse. 

The cited para. [0130] mentions that if the origin of the answer is authenticated as coming 
from the database, the security system performs a check whether the action is requested. If not, 
the security system can ask permission from the user or terminate the process, tell the user that 
something has not been done or the request does not exist. If authorized, it passes the parameters 
of the call to the hooked function. 

Again the cited Mayer concerns invoking the security system to check the permission for 
a hooked function call. Nowhere does this cited para. [0130] anywhere disclose a request to add 
a target file to the file system and then deciding whether to block or allow the request to add the 
file based on the type and size of the file exceed the threshold. There is no disclosure or mention 
in the cited para. [0130] of allowing or blocking the adding of a file based on the type and size of 
the file. Instead, the cited Mayer concerns monitoring, checking and authorizing access for a 
hooked function. 

Accordingly, claims 9, 21, and 34 provide additional grounds of patentability over the 
cited art because the additional requirements of these claims are not disclosed in the cited art. 

Claims 10, 22, and 35 depend from claims 1,17, and 26 and further require that 
processing of the file request and the rule is performed by a program executing in a kernel of an 
operating system to process all requests directed to the file system, wherein the program 
comprises an extension of the file system. 

The Examiner cited para. [0066] of Mayer as disclosing the additional requirements of 
these claims. (Office Action, pg. 7) Applicants traverse. 

The cited para. [0066] mentions that an operating system (OS) is responsible for 
controlling the allocation and usage of computer hardware resources such as memory, CPU time, 
disk space. 

Nowhere does the cited para. [0066] anywhere disclose that the processing of the file 
request and rule is performed by a program executing in a kernel of the operating system. There 
is no mention of a kernel or where the monitoring is performed in the cited para. [0066]. 

Accordmgly, claims 10, 22, and 35 provide additional grounds of patentability over the 
cited art because the additional requirements of these claims are not disclosed in the cited art. 
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Conclusion 



For all the above reasons, Applicant submits that the pending claims 1-10, 17-22, and 26- 
35 are patentable over the art of record. Applicants have not added any claims. Nonetheless, 
should any additional fees be required, please charge Deposit Account No. 09-0466. 

The attorney of record invites the Examiner to contact him at (310) 553-7977 if the 
Examiner believes such contact would advance the prosecution of the case. 

Dated: August 2, 2006 Bv: /David Victor/ 



Please direct all correspondences to: 
David Victor 

Konrad Raynes & Victor, LLP 
315 South Beverly Drive, Ste. 210 
Beverly Hills, CA 90212 
Tel: 310-553-7977 
Fax:310-556-7984 



David W. Victor 
Registration No. 39,867 
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